top of page

Vietnam issues 7 new cybersecurity decrees: what businesses need to prepare for

On August 19, 2026, the Vietnamese Government issued seven decrees, numbered 327/2026/ND-CP through 333/2026/ND-CP, covering online security violations, misinformation, cybersecurity forces, personal data, information systems and cybersecurity services. Most took effect immediately on August 19, while Decree 328/2026/ND-CP will take effect on October 5, 2026.

Vietnam’s cybersecurity regulatory framework has entered a new implementation phase. Rather than setting only broad security principles, the seven newly issued decrees introduce more detailed obligations for information system owners, digital service providers, organizations processing personal data and companies providing cybersecurity products and services.

The decrees follow the entry into force of Vietnam’s 2025 Law on Cybersecurity on July 1, 2026. The new law consolidates a number of provisions previously governed separately by the 2015 Law on Cyberinformation Security and the 2018 Law on Cybersecurity, moving toward a more unified regulatory framework for cyberspace.

Businesses seeking broader context can also review IPSIP’s analysis of the 2025 Law on Cybersecurity and its role in strengthening trust in Vietnam’s digital environment.

vietnam-7-cybersecurity-decrees-2026
Everything needs to know about Vietnam’s 7 new cybersecurity decrees 2026

What do the seven new cybersecurity decrees cover?

On August 19, 2026, the Government issued seven consecutive decrees from Decree 327 to Decree 333. Together, they address a wide range of cybersecurity issues, from preventing activities that threaten national security to protecting information systems, personal data and the provision of cybersecurity services.

Decree

Main Scope

Key Business Relevance

327/2026/ND-CP

Prevention and handling of information and activities that infringe national security, social order and safety in cyberspace

Requires system owners and service providers to strengthen monitoring, data preservation and incident coordination capabilities

328/2026/ND-CP

Prevention and handling of fake news and false information

Establishes processes for detecting, verifying, labeling, warning against and removing false information

329/2026/ND-CP

Cybersecurity protection forces

Clarifies organization, operating principles and coordination mechanisms for cybersecurity forces

330/2026/ND-CP

Administrative penalties for cybersecurity and personal data protection violations

Introduces specific violations, penalties and remediation measures

331/2026/ND-CP

Cybersecurity protection for information systems

Introduces system classification levels and security requirements based on risk and importance

332/2026/ND-CP

Cybersecurity product and service businesses

Sets legal, technical, personnel and licensing requirements for providers

333/2026/ND-CP

Detailed implementation of several provisions of the Law on Cybersecurity

Clarifies obligations for Internet and online service providers

The effective dates are not identical across all seven decrees. Decree 328/2026/ND-CP on fake news and false information will take effect on October 5, 2026, while Decree 327 and Decrees 329–333 took effect on August 19, 2026.

Which requirements could have the greatest impact on businesses?

For most companies outside the digital platform sector, Decrees 330 and 331, together with relevant requirements under Decree 327, are among the regulations that should be reviewed first. Organizations providing Internet-based or online services should also pay particular attention to Decree 333.

Decree 327 requires information system owners and service providers to apply management and technical measures to identify risks, monitor systems and detect activities showing signs of cybersecurity violations. When such signs are detected, relevant organizations may also be required to limit potential damage, preserve electronic data and cooperate with competent authorities.

For certain requests involving electronic information or data, the response deadline may be up to 24 hours under normal circumstances and as short as three hours in urgent cases.

Decree 331 further shifts cybersecurity management from broad security requirements toward a five-level information system classification model.

For example, an information system serving individuals or businesses and processing basic personal data of 100,000 or more data subjects, or sensitive personal data of 10,000 or more data subjects, may meet one of the criteria associated with Level 3 systems.

Security measures under the decree include establishing cybersecurity policies across the system lifecycle, implementing storage and backup requirements, determining and documenting security levels, conducting assessments and applying appropriate technical controls before systems are placed into operation.

How does decree 330 change the personal data protection landscape?

Decree 330/2026/ND-CP strengthens the enforcement framework surrounding cybersecurity and personal data protection obligations.

The decree contains 82 articles covering administrative violations, penalties, remediation measures and enforcement authority.

According to information published by the Government News portal, obstructing or interfering with personal data protection activities may result in fines of up to VND 60 million. Processing personal data collected without the data subject’s consent may be subject to fines of up to VND 50 million.

Separate penalties may also apply to activities such as continuing to process personal data after a valid request to stop, or treating a data subject’s silence as consent.

For businesses, this means personal data protection can no longer be treated purely as a legal or compliance responsibility. Consent management, access control, data retention, deletion workflows, audit logs and processes for responding to data-subject requests all depend on the actual design and operation of IT systems.

Organizations reviewing their data governance programs can also compare their current controls with the key requirements and prohibited practices under Vietnam’s Personal Data Protection Law.

For sensitive information or data stored in cloud environments, encryption and access control should be considered part of the broader risk-reduction strategy rather than controls introduced only after a security incident.

What additional responsibilities do decrees 328 and 333 place on digital platforms?

Decree 328 establishes a structured process for handling fake news and false information, including detection, verification, labeling, public warnings, access restriction, removal and enforcement actions.

The scope includes Internet service providers, social media companies and cross-border information service providers operating in Vietnam or providing services to users in Vietnam.

Decree 333 goes further into the cybersecurity obligations of domestic and foreign companies providing telecommunications, Internet and value-added online services in the Vietnamese market.

The decree addresses areas such as user authentication, account protection, responding to lawful information requests and handling content or services that violate cybersecurity requirements.

According to the Government News portal, some requests for information must be fulfilled within 24 hours, with the deadline potentially reduced to three hours in urgent circumstances.

Certain requests to restrict access to or remove violating content may need to be completed within 24 hours, or within six hours in urgent cases involving national security.

What should businesses do after the seven decrees take effect?

Not every provision applies equally to every organization. The first priority is therefore to determine what type of regulated entity the business is, what systems it operates and what categories of data it processes.

A practical first-stage checklist includes:

  • Build an inventory of systems and data: Identify websites, applications, cloud environments, servers, APIs, databases, internal platforms and third-party connections.

  • Review information system classification: Compare systems against Decree 331 criteria, particularly those processing large volumes of personal data or providing online services.

  • Review personal data workflows: Assess legal basis, consent, access permissions, retention periods, deletion processes and activity logging.

  • Preserve logs and electronic evidence: Identify log sources, retention periods and responsibilities when potential security violations are detected.

  • Assess detection capability: Review the coverage and effectiveness of EDR/XDR, SIEM, firewalls, IDS/IPS and existing monitoring platforms.

  • Update incident response procedures: Define who receives alerts, who can authorize containment actions, who works with competent authorities and who manages communications.

  • Review service providers: Organizations using MSSPs, cloud providers or outsourced cybersecurity services should assess their technical capabilities, responsibilities and applicable legal requirements.

  • Train relevant teams: IT, Security, Legal, Compliance and data governance teams should understand and operate under coordinated procedures.

For critical or continuously operating systems, organizations may also consider a 24/7 Security Operations Center for centralized monitoring and coordinated incident response.

The objective is not simply to generate more alerts. Security events must be verified, escalated and handled through clearly defined operational processes.

What does IPSIP Vietnam’s cybersecurity perspective highlight?

Decree 327 places particular emphasis on early risk detection and the preservation of electronic data when suspicious activities are identified.

Cybersecurity weaknesses can increasingly create multiple forms of exposure at the same time: operational disruption, data compromise, regulatory liability and reputational damage.

Decree 330 introduces direct enforcement mechanisms for certain personal data obligations, while Decree 331 links technical protection requirements to the classification and importance of information systems.

Cybersecurity compliance and technical security should be treated as components of the same risk management framework.

The Vietnamese Government’s issuance of Decrees 327/2026/ND-CP through 333/2026/ND-CP represents a significant step in implementing the 2025 Law on Cybersecurity.

For Vietnamese businesses, the immediate priority should not simply be acquiring additional cybersecurity tools. Organizations should first determine which systems and data fall within the scope of the new requirements, then review their monitoring, logging, incident response and data governance capabilities.

References

Comments


follow ipsip vietnam.png
40051abd5a76713af8f015988fc6780e-blue-phone-icon-with-a-wave-on-it.webp
Logo-Zalo-Arc.webp
pngtree-minimal-calendar-icon-vector-png-image_21233134.png
IPSIP logo transparent.png

IPSIP VIETNAM ONE MEMBER LIMITED LIABILITY COMPANY (IPSIP VIETNAM OMLLC)

Tax code: 0313859600

🏢 SH05.01, B4 Street, Saritown Area, An Khanh Ward, Ho Chi Minh City, Vietnam

​☎  +84 918 397 489

  • Linkedin
  • Facebook
  • TikTok
  • Email liên hệ
png-clipart-iso-iec-27001-information-security-management-iso-iec-27002-international-orga
soc 2 type ii

Our Services

Sign up to receive in-depth cybersecurity documents and news from IPSIP Vietnam.

bottom of page